CryptographyUnit 39 min read
Symmetric Key Cryptography: Ciphers, Modes, and Real-World Security
Unit 3 of Cryptography explores symmetric key algorithms (stream/block ciphers), their mathematical foundations, modes of operation, and practical applications like eSewa transactions and WhatsApp end-to-end encryption. Learn how keys are shared, how AES/DES work internally, and why symmetric systems dominate performan
Core Concepts: What is Symmetric Key Cryptography?
Symmetric key cryptography is a shared-secret system where the same key is used for both encryption and decryption. Unlike asymmetric cryptography (Unit 5), it relies on speed and efficiency rather than key distribution complexity. The core idea: if Alice and Bob share a secret key, they can encrypt/decrypt messages without needing a third party.
Why Symmetric Keys?
- Speed: AES (a symmetric cipher) encrypts data at ~10 Gbps on modern CPUs.
- Simplicity: No complex math (like RSA’s modular exponentiation).
- Use Cases: Encrypting files, databases, network traffic (TLS uses symmetric keys after handshake).
classDiagram
class SymmetricKey {
+Key: Shared Secret
+Encryption: Plaintext + Key → Ciphertext
+Decryption: Ciphertext + Key → Plaintext
}
class AsymmetricKey {
+KeyPair: Public/Private
+Encryption: Plaintext + Public → Ciphertext
+Decryption: Ciphertext + Private → Plaintext
}
SymmetricKey --> "Uses" Key
AsymmetricKey --> "Uses" KeyPair
note for SymmetricKey
Faster, but key distribution is hard
end note1. Stream Ciphers: One-Time Pad and Modern Alternatives
Stream ciphers encrypt one bit/byte at a time using a keystream. The simplest (and theoretically unbreakable) is the One-Time Pad (OTP).
One-Time Pad (OTP)
- How it works: XOR plaintext with a truly random key (same length as plaintext).
- Security: Perfect secrecy if:
- Key is random.
- Key is never reused.
- Key is as long as plaintext.
- Real-World Use: Military communications, diplomatic cables.
Example: Encrypt "HELLO" with key "XMCKL" (OTP):
P: H(0x48) E(0x45) L(0x4C) L(0x4C) O(0x4F)
K: X(0x58) M(0x4D) C(0x43) K(0x4B) L(0x4C)
C: P⊕K = 70 18 09 07 03 → "p␊␉␇␇" (binary)
Decrypt: XOR ciphertext with the same key to recover P.
Weakness: Key distribution is impractical for most uses.
2. Block Ciphers: AES, DES, and How They Work
Block ciphers split data into fixed-size blocks (e.g., 64-bit for DES, 128-bit for AES) and apply the same key to each block.
Feistel Cipher Structure (DES Example)
DES (Data Encryption Standard) uses a 16-round Feistel network:
- Split block into left (L) and right (R) halves.
- For each round:
Lₙ₊₁ = RₙRₙ₊₁ = Lₙ ⊕ f(Rₙ, Kₙ)(wherefis a round function,Kₙis a subkey).
- After 16 rounds, swap halves and concatenate.
stateDiagram-v2
[*] --> InitialSplit: L0, R0
state InitialSplit {
[*] --> Round1: L0, R0
Round1 --> Round2: L1=R0, R1=L0⊕f(R0,K1)
Round2 --> ...
Round16 --> FinalSwap: L16, R16
}
FinalSwap --> [*]: Ciphertext = R16 || L16Weak Keys in DES: Keys where all bits are 0 or 1 (e.g., 0x0000000000000000) or complementary halves (e.g., 0x0101010100000000). These reduce effective rounds.
Advanced Encryption Standard (AES)
AES is the modern standard (128/192/256-bit keys). It uses:
- SubBytes: Non-linear substitution (S-box).
- ShiftRows: Byte shifting.
- MixColumns: Linear mixing.
- AddRoundKey: XOR with round key.
Example: AES-128 encrypts "Hello" (padded to 16 bytes) with key "000102030405060708090A0B0C0D0E0F".
3. Block Cipher Modes of Operation
Modes define how blocks are processed for longer messages. Common modes:
| Mode | Description | Security Notes |
|---|---|---|
| ECB | Encrypt each block independently. | Insecure: Identical plaintext → identical ciphertext. |
| CBC | XOR plaintext with previous ciphertext (IV for first block). | Secure if IV is random. |
| CFB/CTR | Stream-like operation (CTR is parallelizable). | CTR is fastest. |
| GCM | Authenticated encryption (AES-GCM). | Used in TLS 1.3. |
Example (CBC Mode):
Plaintext: P1 || P2 || P3
IV: IV
Ciphertext: E(K, IV ⊕ P1) || E(K, C1 ⊕ P2) || E(K, C2 ⊕ P3)
4. Hill Cipher: A Matrix-Based Example
The Hill cipher encrypts blocks of letters using matrix multiplication over modulo 26.
Example: Encrypt "HELLO" with key:
K = [7 8]
[11 11]
- Convert letters to numbers:
H=7, E=4, L=11, L=11, O=14. - Split into blocks:
[7,4]and[11,11]. - Multiply:
Next block:[7 8][7] [7*7+8*4] [49+32] [81 mod 26 = 5 (F)] [11 11][4] = [11*7+11*4] [77+44] [121 mod 26 = 13 (N)][7 8][11] [7*11+8*11] [77+88] [165 mod 26 = 13 (N)] [11 11][11] = [11*11+11*11] [121+121] [242 mod 26 = 2 (C)] - Ciphertext:
"FNNC"(decrypt similarly with inverse matrix).
Weakness: Small keys → vulnerable to frequency analysis.
5. Playfair Cipher: A Classic Substitution Cipher
The Playfair cipher encrypts digraphs (pairs of letters) using a 5×5 matrix.
Example: Encrypt "TURINGTEST" with key "HELLOWORLD":
- Create matrix (fill with remaining letters, skip
J):H E L O W R D A B C F G I K M N P Q S T U V X Y Z - Split plaintext into digraphs (insert
Xas filler):TU | RI | NG | XE | ST - Encrypt rules:
- Same row: shift right (e.g.,
TU→HP). - Same column: shift down (e.g.,
RI→EL). - Rectangle: replace with diagonal (e.g.,
NG→BO).
- Same row: shift right (e.g.,
- Ciphertext:
"HP EL BO XA DM".
Weakness: Limited to 25 letters (no J), vulnerable to known-plaintext attacks.
6. Vernam Cipher: The Stream Cipher Standard
The Vernam cipher is a practical OTP using a repeating keystream (unlike true OTP). It’s the basis for A5/1 (GSM encryption).
Example: Encrypt "HELLO" with key "FAIL" (repeated):
P: H(0x48) E(0x45) L(0x4C) L(0x4C) O(0x4F)
K: F(0x46) A(0x41) I(0x49) L(0x4C) F(0x46)
C: P⊕K = 20 04 8D 00 0B → " ␊⌍␇"
Decrypt: XOR again with the same key.
Weakness: Keystream must be truly random (A5/1 was broken due to weak RNG).
In the Real World
eSewa (Nepal):
- Uses AES-256 in CBC mode to encrypt payment data between your phone and eSewa’s servers.
- The symmetric key is derived from your PIN + device ID (never transmitted).
WhatsApp End-to-End Encryption:
- Signal Protocol (a hybrid system) uses AES-256 in CTR mode for message encryption after a Diffie-Hellman key exchange.
- Example: When you send a message to a friend, WhatsApp generates a one-time symmetric key, encrypts the message with AES, and deletes the key after delivery.
NTC’s Network Security:
- NTC uses AES-128 in GCM mode to secure fiber-optic backhaul traffic between base stations.
- Example: If a hacker intercepts traffic, they see only encrypted packets (e.g.,
0xA3F7...) because the IV + GCM tag prevents tampering.
Khalti’s Tokenization:
- When you link a bank card to Khalti, your card number is replaced with a symmetric-key-encrypted token (AES-128).
- Real Scenario: If a merchant’s database is hacked, attackers get tokens like
tok_abc123, not your actual card number.
Daraz’s Order Processing:
- Daraz’s inventory system uses DES (legacy) or AES to encrypt stock updates between warehouses and the central database.
- Example: If a seller uploads 100 units of a product, the system encrypts the update with a shared key before storing it in the database.
Exam Tip: How to Score Full Marks
For Hill/Playfair/Vernam:
- Always show step-by-step matrix multiplication or XOR tables.
- Label each step (e.g., "Step 1: Convert letters to numbers").
- Common mistake: Forgetting modulo 26 in Hill cipher.
For AES/DES:
- Draw the Feistel structure or AES rounds in your answer.
- For key expansion, show how subkeys are derived (e.g., AES’s
RCON). - Example question: "Explain the round operation in IDEA" → Draw the 3-step process (multiplication, addition, XOR).
For Modes of Operation:
- Compare ECB vs CBC vs CTR in a table.
- Example: "Why is ECB insecure?" → Show how identical plaintext blocks produce identical ciphertext.
For Real-World Applications:
- Link AES to eSewa/Khalti or OTP to military use.
- Example: "How does WhatsApp use symmetric keys?" → Explain Signal Protocol’s double ratchet.
Weak Keys:
- For DES: Mention all-zero, all-one, or complementary halves.
- For Hill cipher: Say small matrices (2x2) are weak.
AES SubBytes, ShiftRows, MixColumns, AddRoundKey steps (Image: Jeongysu, CC BY-SA 3.0, via Wikimedia Commons)
Based on the TU BSc CSIT syllabus for Cryptography (CSC316), unit 3.
Discussion
Loading…